icon-zia.svg
Secure Internet and SaaS Access (ZIA)

Monitoring or Blocking Outbound Content by Data Size

You might want to leverage Zscaler's DLP policy to monitor or block specific types of outbound content by data size, without scanning for specific data within the content. For example, you could block outbound image files (such as GIF or JPEG), but only those that exceed a certain data size. In Policy > File Type Control, you can set policy to block image files, but you cannot specify data size.

For this scenario, you can leverage the Rule Without Content Inspection policy option. When configuring the policy, you can specify the criteria Zscaler uses for monitoring or blocking content, but refrain from specifying an ICAP server. Zscaler will monitor or block outbound content based on the criteria you specify, but will not send content to any external DLP engines. The illustration below details the process that takes place when you configure DLP policies for this scenario:

Diagram showing the process that takes place when you configure DLP policies for the External DLP Engine policy option

To configure rules for this scenario:

  1. Configure your DLP notification templates. Once configured, email notifications are sent to your organization's auditor when DLP rules are applied to users' content.
  2. Define your DLP policy rule without content inspection.
Related Articles
About Data Loss PreventionConfiguring DLP Policy Rules with Content InspectionConfiguring DLP Policy Rules without Content InspectionConfiguring DLP Policy Rules with Evaluate All Rules Mode EnabledConfiguring DLP Advanced SettingsMonitoring or Blocking Outbound Content by Data SizeDLP Policy Configuration Example: Match OnlyStep-by-Step Configuration Guide for Webex Teams Real-Time DLPAccessing the DSPM Admin Portal using SSO